LO1.2 Confidentiality Protocols Flashcards
The definition of ‘confidentiality protocols’ is…
A promise to protect personal or business information from being shared more widely
In a business context, what types of information might be considered to be confidential?
Confidentiality in business might include:
Customer data, financial data, business processes, trade secrets (eg recipes), plans and strategies
Give 3 reasons why confidentiality needs to be maintained in a business situation..
Confidentiality needs to be maintained… 1. as it is a legal requirement, 2. to protect the reputation of a business, and 3. to retain competitive advantage
Explain how a business can maintain confidentiality by using practical measure #1: NEED TO KNOW BASIS
Keeping the number of staff who know the confidential information to a minimum
Explain how a business can maintain confidentiality by using practical measure #2: USING IT SYSTEMS
Restricting access to files or server areas, using BCC to avoid sharing email address details, not “replying to all” or copying in “all staff” on emails
Explain how a business can maintain confidentiality by using practical measure #3: CONTRACT OF EMPLOYMENT
Making disclosure of confidential information a matter of gross misconduct (i.e. a sackable offence)
Explain how a business can maintain confidentiality by using practical measure #4: NON-DISCLOSURE AGREEMENT (NDA)
Asking stakeholders to sign NDAs which are legally binging contracts (e.g. recipes given to suppliers of ingredients)
What are the two types of system of storing confidential documentation securely?
MANUAL SYSTEMS - locked filing cabinets and shredding paper waste, and ELECTRONIC SYSTEMS - password protection and printer retrieval log-ins
How can breaching confidentiality have significant implications on: A the BUSINESS, and B the INDIVIDUAL?
BUSINESS: legal action, financial penalties (fines), damage to reputation, loss of competitive advantage. INDIVIDUAL: disciplinary action, warnings or dismissal.
When is it OK to breach confidentiality?
ILLEGAL ACTIVITY: duty to report staff who are suspected of breaking the law. EMERGENCIES: medical or physical emergency to contact relatives